CVE Tools

Snowpick: Open-source ServiceNow exposure scanner

Help Net SecurityBy Mirko Zorz

ResearchServiceNow

Our summary

Bishop Fox has developed and released an open-source tool named Snowpick that identifies unauthenticated data exposure in ServiceNow platforms. During authorized penetration tests, the firm scanned 166 ServiceNow instances and found that 31% had exposed data accessible without credentials. These vulnerabilities stemmed from misconfigurations and access control flaws rather than new zero-day exploits. The tool uses public endpoints like Service Portal widgets and the Table REST API to detect leaked information such as ticket attachments, knowledge base entries, and service catalog details. Organizations are advised to audit their configurations using Snowpick to prevent potential incidents.

Read at Help Net Security

Help Net Security publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store